NASA Best Practices Guide for Mission Cybersecurity
GR-AUTH-02

Risk-informed Authorization for Non-Program Users Function

Parent: GR

Description

The mission should use only verified identities when provisioning authenticators to organizational users and processes acting on behalf of users.

Mapped SPARTA techniques

2 techniques

  • The practice requires verified identity before provisioning authenticators to users acting on the mission's behalf, which governs how an academic or international collaborator is admitted without constraining what they do once admitted.

  • IA-0009.02VendorST0003
    addresses
    moderate

    Vendor access is provisioned under the same identity-verification obligation, which governs the admission step of the trusted relationship the technique abuses.

Cross-framework references

Relationships published by the source frameworks themselves, reproduced here with attribution. They are not SafeMode Space mappings and carry no confidence rating of ours.

Crosswalks to 2 in NIST SP 800-53 Rev. 5

Cite as SafeMode Space, nasa-bpg GR-AUTH-02.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.